This update for python-tornado fixes the following issues:
CVE-2023-54397: Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of
Content-Length headers accepting non-standard characters. At (bsc#1280689).
CVE-2024-58384: CRLF injection in CurlAsyncHTTPClient headers (bsc#1281059).
CVE-2026-91990: splitting of multipart data before validation of the max_parts limit allows for resource exhaustion
and a denial of service (bsc#1281439).
CVE-2026-91991: incomplete fix for cookie attribute injection allows for cookie validation bypass via semicolon-
delimited data in capitalized parameters (bsc#1281440).